CVE-2026-68360

Unknown

Last modified

CVE-2026-68360 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop()..

Description

In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 0975c42ed2a3bf32125a920e5d19194289126210; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < c7757db58957ac20cdec6ce575dbd44a6375664e; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 56d2deb6448378118dbe68c4fbb3fbae5f65b18c; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 1a634f464d6153dfa4d7e73a3d78236b65a64ee9; >= 40c3a445422579db8ad96c234dbe6c0ab3f6b936, < 94c87871b051d7ad758828a805215a2ec194512a
LinuxLinux5.9

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68360?
In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop Calling hid_hw_stop() does not stop the device IO. This results in a race condition between hid_input_report() and the point immediately following the execution of hid_device_io_start() within the driver probe function. If the probe operation fails after "io start" has been initiated, this race condition will result in a UAF vulnerability. Fix the problem by calling hid_device_io_stop() before calling hid_hw_stop().
How severe is CVE-2026-68360?
Severity scoring for CVE-2026-68360 is pending analysis.
How do I fix CVE-2026-68360?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68360?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST